Re: Re: LiveUser password encryption
| From: | Matte Edens | Date: | Thu, 10 Jun 2004 21:23:26 +0000 |
| Subject: | Re: Re: LiveUser password encryption | ||
| References: | 1 2 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-13093@lists.php.net to get a copy of this message | ||
I've got the same problem to take care of. Been using PASSWORD() forever with MySQL without realizing that I should have been using either MD5() or SHA(). Now I have to manage a conversion. My thought was (and this is a LITTLE off-topic) was ...
1. Temporarily add a enum(T/F) field to the user table named
"passwd_converted" (or something to that effect)2. Before the user logs in, check the value of the "passwd_converted"
field.3. If "F" then
1. User form contains a hidden field "changefunc" to indicate
that the password needs updating with the value of the new
function
2. We know to use PASSWORD() to validate password
4. If "T" then
1. nothing to change since the password field contains the
correct password hash.
2. use the new function to validate password
5. After the user has logged in successfully, if we needed to change
the password hash then we update the password field and the
"passwd_converted" field.
6. QED
That'll probably be my path. FWIW, my $0.02.
If anyone has a better suggestion, I'm open to hearing it.
--
matte - matte@arubanetworks.com
webmonkey / arubanetworks.com / airheads04.com / wi-fi-it.com
Michael Wallner wrote:
> mishal@centrum.cz wrote:
>
>> my question is: is it possible to use liveuser with mysql password
>> function?
>
>
> Hi, unfortunately I don't know the internals of
> LiveUser, but one thing I can say for sure is,
> that using MySQLs PASSWORD() is definitely a
> bad thing [tm]. MySQL AB itself states that this function may be
> changed without warning.
>
> You should probably watch out for a way
> to change the current system to use a more reliable way of storing
> your passwords.